Using biglumber services for the gpg Key signing party ?
Hi, I recently started using my gpg again - after a year or two of inactivity. I've participated to previous Fosdems key signing parties in previous editions of Fosdem, and it usually ends up in a interesting mess. The best organized one was one where we could print ourselves the complete keyring, that was generated by sending our public keys to a know email address. But This doesn't prevent the work that needs to be done afterwards. One of the annoying parts is when you sign a key and that key is never counter signed. I'd like to propose to use biglumber.com's services to organize the technical part of the key-signing party. I know this means relying on a third party service but I think It would make dealling with the organization of the event way easier. How would this work ? 1) Someone would create a Fosdem 2010 event with a valid date on biglumber.com 2) The event is announced like each year and a link to the biglumber event is given with a End date to add your key to it. 3) People wishing to participate to the event can add their key to the event. 4) People should print the event key list (and use it at the party), before coming to Fosdem and after the End date given in 2. With this most of the technical parts for the organization is solved. In order to add your key to the key ring users need to register on biglumber which some of the attendees might object. But the good news about having to register is that people then can use the biglumber escrow service - meaning that their signature will only be released and updated - only when both person that have signed have uploaded. This part of the process make the aftermath a bit longer but insures that key signing will be symetric. Thoughts, ideas , wdyt ? Ludovic ps, and no I'm not affiliated with biglumbers.com -- http://perso.hirlimann.net/~ludo/blog/ http://flickr.com/photos/lhirlimann
On Mon, Aug 24, 2009 at 09:09:39AM +0200, Ludovic Hirlimann wrote:
With this most of the technical parts for the organization is solved.
In order to add your key to the key ring users need to register on biglumber which some of the attendees might object. But the good news about having to register is that people then can use the biglumber escrow service - meaning that their signature will only be released and updated - only when both person that have signed have uploaded. This part of the process make the aftermath a bit longer but insures that key signing will be symetric.
Just one question: why? Sure, it's a pity if some keys are not cross-signed. But it's not fatal either, is it? There are a few problems with your proposal: - One of the things you're supposed to do when signing someone's key is checking that the email addresses on the key actually belong to the person owning the key. I usually do this by way of the 'caff' script, which signs the key, then encrypts it to the owner's mail address, and sends the encrypted signature off. Using such an escrow service would probably make this quite a bit harder, if not impossible. - It requires people to jump through hoops in order to sign keys. That's never a good thing, because signing keys is boring, and you want people to be able to do things the way they usually do, rather than the particular way this particular key signing party requires you to. Otherwise they're likely to postpone it until they forget. - On the subject of forgetting: receiving key signatures is an excellent way to remember that you have to sign them. Having an escrow service takes that away. Of course, I stopped doing key signing parties (my key is well-connected now anyway), so feel free to disregard anything I said. -- The biometric identification system at the gates of the CIA headquarters works because there's a guard with a large gun making sure no one is trying to fool the system. http://www.schneier.com/blog/archives/2009/01/biometrics.html
Hey, Can someone explain what the purpose of the Key signing party is, or provide a reference to some helpful docs? Cheers, Jeroen De Dauw Forum: code.bn2vs.com Blog: blog.bn2vs.com Skype: rts.bn.vs ; Xfire: bn2vs Don't panic. Don't be evil. 70 72 6F 67 72 61 6D 6D 69 6E 67 20 34 20 6C 69 66 65! ________________________________ From: Wouter Verhelst <wouter@debian.org> To: FOSDEM visitors <fosdem@lists.fosdem.org> Sent: Monday, August 24, 2009 10:09:05 AM Subject: Re: [FOSDEM] Using biglumber services for the gpg Key signing party ? On Mon, Aug 24, 2009 at 09:09:39AM +0200, Ludovic Hirlimann wrote:
With this most of the technical parts for the organization is solved.
In order to add your key to the key ring users need to register on biglumber which some of the attendees might object. But the good news about having to register is that people then can use the biglumber escrow service - meaning that their signature will only be released and updated - only when both person that have signed have uploaded. This part of the process make the aftermath a bit longer but insures that key signing will be symetric.
Just one question: why? Sure, it's a pity if some keys are not cross-signed. But it's not fatal either, is it? There are a few problems with your proposal: - One of the things you're supposed to do when signing someone's key is checking that the email addresses on the key actually belong to the person owning the key. I usually do this by way of the 'caff' script, which signs the key, then encrypts it to the owner's mail address, and sends the encrypted signature off. Using such an escrow service would probably make this quite a bit harder, if not impossible. - It requires people to jump through hoops in order to sign keys. That's never a good thing, because signing keys is boring, and you want people to be able to do things the way they usually do, rather than the particular way this particular key signing party requires you to. Otherwise they're likely to postpone it until they forget. - On the subject of forgetting: receiving key signatures is an excellent way to remember that you have to sign them. Having an escrow service takes that away. Of course, I stopped doing key signing parties (my key is well-connected now anyway), so feel free to disregard anything I said. -- The biometric identification system at the gates of the CIA headquarters works because there's a guard with a large gun making sure no one is trying to fool the system. http://www.schneier.com/blog/archives/2009/01/biometrics.html __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com
On Monday 24 Aug 2009 09:56:25 jeroen De Dauw wrote:
Can someone explain what the purpose of the Key signing party is, or provide a reference to some helpful docs?
http://www.cryptnet.net/fdp/crypto/keysigning_party/en/keysigning_party.html Google is your friend :) -- Richard www.sheflug.org.uk
I could use that service, since the last keysigning party I've tried to sign the keys several times always giving up after not being able to get the caff-package to send the keys to the recipients.. Probably I've got 200-300 messages in the send queue in the mail spool... ;I Cheers, Matthias Andersson
participants (5)
-
jeroen De Dauw -
Ludovic Hirlimann -
Matthias Andersson -
Richard Ibbotson -
Wouter Verhelst